Skip to content

BusinessIntents data hosting

Where service data lives and how it is protected.

BusinessIntents runs on Amazon Web Services in the Frankfurt region. Each customer has its own database, backups are taken daily and kept for 30 days, and service data stays in the European Union.

This page describes the providers, locations, tenant separation, backups, recovery, logs, access, and deletion that apply to data in the BusinessIntents service.

Security and privacy enquiries, including hosting and data-residency questions: privacy@codbex.com. All other enquiries: office@codbex.com.

LocationsIsolationBackupsRecoveryAccess

Document governance

The accountable owner and applicable version.

This page is reviewed whenever providers, regions, architecture, backup policy, or access practices change.

Infrastructure owner
Legal Advisor, codbex ltd
Effective date
24 September 2026
Last reviewed
24 September 2026
Review frequency
At least once a year, and before any change of hosting provider, region, backup policy, or production-access practice.

Location and responsibility

The full data path, not only the primary server.

Customer data in BusinessIntents is processed and stored by Amazon Web Services in the Frankfurt region (eu-central-1), Germany, including the application, the customer databases, backups, and service logs. System emails from the application are sent through Amazon SES. Correspondence with our office and privacy mailboxes and subscription payments use separate providers, described below and on the Subprocessors page.

Current product evidence

Separation between customers.

Each customer's records and settings are held in a database dedicated to that customer. Inside the application, group permissions and administrator-only areas control what each user can see and do.

01

Tenant-scoped configuration

Each tenant begins with its own seeded settings, and configuration changes are documented as not affecting another tenant.

Review configuration
02

Application authorization

Group permissions and administrator-only areas control what users can see and do inside the application.

Review application access
03

Separate databases

Every customer has its own database. One customer's business records are not stored in the same database as another customer's.

Summary

Location, resilience, and lifecycle at a glance.

The key facts a buyer needs to understand the normal data path and what happens when systems fail or a subscription ends.

01

Primary processing

Amazon Web Services EMEA SARL, Frankfurt region, Germany. BusinessIntents is currently offered from this region only.

02

Resilience

Daily backups kept for 30 days in the EU, stored separately from the production databases.

03

Lifecycle

30 days to export after the subscription ends, then deletion from production; backup copies expire within a further 30 days.

Hosting and resilience

The hosting and resilience record.

Where an option is not offered, this page says so directly.

Hosting providers and locations

Application servers, customer databases, file storage, backups, and service logs: Amazon Web Services EMEA SARL (Luxembourg), AWS Frankfurt region (eu-central-1), Germany; all customer data. System emails sent by the application, such as notifications: Amazon SES, operated by the same AWS entity in the EU; recipient address and message content. Office and privacy mailboxes: Google Workspace, Google Cloud EMEA Limited (Ireland); enquiry and support correspondence, including any customer data a customer chooses to send by email. Subscription payments: Stripe Payments Europe, Limited (Ireland); billing contact and payment data. Public website businessintents.com: GitHub Pages, GitHub, Inc. (USA); visitors' IP addresses and request data only, no customer data.

Residency and transfers

All customers are hosted in the AWS Frankfurt region; choosing another region is not currently offered. Customer data in the service, including backups and logs, is stored in the EU and is not transferred outside the European Economic Area. codbex ltd's contract with AWS includes the AWS Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses for any access from outside the EEA. Email correspondence in Google Workspace and payment data at Stripe may be processed outside the EEA under the EU–U.S. Data Privacy Framework and Standard Contractual Clauses.

Tenant isolation and network architecture

Each customer has its own separate database, so business records of different customers are not mixed in one database. Configuration is scoped to the customer: settings changes in one tenant do not affect another. Within a customer's environment, access depends on group permissions, and administrator functions are limited to administrators.

Backups

Customer databases are backed up daily. Backups are stored in the EU, separately from the production databases, and are deleted automatically after 30 days. Backups are used only to restore the service and are not used for any other purpose.

Availability and disaster recovery

codbex ltd uses commercially reasonable efforts to keep the service available. Because backups are taken daily, the recovery point after a major failure is up to 24 hours: data entered after the most recent backup may need to be re-entered. No availability percentage or recovery time objective is guaranteed unless it is agreed in a separate Service Level Agreement.

Logs and telemetry

Application, access, and security logs are stored in the AWS Frankfurt region. They can contain user identifiers, IP addresses, timestamps, and the actions performed. They are accessible only to personnel who operate and secure the service, and are kept only as long as needed to protect the service and investigate incidents, after which they are deleted or anonymized.

Production and support access

Access to production infrastructure is limited to authorized codbex ltd personnel who need it to operate the service. codbex ltd personnel access a customer's data only when needed to provide support the customer has requested, to maintain or secure the service, or when required by law. AWS acts as an infrastructure provider and processes customer data only under its data processing terms with codbex ltd.

Account closure and deletion

After a subscription ends, the customer has 30 days to export its data. The customer's database is then deleted from production. Backup copies are deleted automatically within a further 30 days as backups expire, so customer data is fully removed within 60 days of the end of the subscription. Data may be retained longer only where the law requires it or where it is needed to establish, exercise, or defend a legal claim. Written confirmation of deletion is available on request from privacy@codbex.com.

Hosting evidence

Documents behind the hosting disclosure.

Documents that are not published here are provided on request.

Hosting architecture overviewNo architecture document is published. Request an overview for due diligence from privacy@codbex.com.
Backup and recovery summaryDaily backups, stored in the EU separately from production, deleted after 30 days; recovery point up to 24 hours; no guaranteed recovery time outside a Service Level Agreement.
Data-location scheduleThe provider and location list is published above under Hosting providers and locations and on the Subprocessors page.

Related trust information

Read hosting together with security, privacy, and suppliers.

The same providers, locations, retention periods, and transfer mechanisms appear on each of these pages.

Hosting questions

Short answers to common hosting questions.

Where is BusinessIntents customer data hosted?

On Amazon Web Services, contracted through Amazon Web Services EMEA SARL, in the Frankfurt region (eu-central-1), Germany. Production databases, files, backups, and service logs are all stored in the EU.

Can a customer choose a data region?

No. BusinessIntents is currently offered only from the AWS Frankfurt region, and customer data in the service is not transferred outside the European Economic Area.

How often is data backed up?

Daily. Backups are stored in the EU separately from the production databases and are deleted automatically after 30 days. In a major failure, data entered after the most recent backup may need to be re-entered.

What happens to data after account deletion?

The customer has 30 days to export its data, after which its database is deleted from production. Backup copies expire within a further 30 days, so the data is fully removed within 60 days, unless the law requires longer retention. Confirmation is available on request.

Hosting due diligence

Ask for the data-location detail your review requires.

Send hosting, residency, and backup questions to privacy@codbex.com.

Security and privacy enquiries, including hosting and data-residency questions: privacy@codbex.com. All other enquiries: office@codbex.com.

The BusinessIntents Business Suite - end-user guide.